Executive brief
A security vulnerability has been identified in Google Chrome's Extensions component. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code within the browser's restricted environment (sandbox). While the sandbox provides a layer of protection, this could still lead to service instability or be used as part of a larger attack to compromise the user's system.
Technical details
A use-after-free (UAF) vulnerability exists in the Extensions component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of extension-related tasks, specifically when handling a crafted HTML page. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website, leading to arbitrary code execution within the Chromium sandbox. This vulnerability is classified as CWE-416. Google has addressed this issue in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD publication date
- 2026-06-30: patched: Chrome version 150.0.7871.47 released